Training and awareness
By Redaktion techport.ai, IT-Beratung · Last updated on
The most common entry into a company network runs through a person who clicks something that looks genuine. That is not an argument against people but an argument for preparation. Attacks by email and telephone today are well made, linguistically flawless, often referencing real transactions and real names from the company.
Awareness works when it is concrete and when reporting is easier than staying silent. It does not work as an annual compliance module with a click-through.
How you notice it
- After a suspicious click nobody speaks up, for fear of consequences.
- Training happens once a year and uses examples that look obviously fraudulent.
- It is unclear who to report a suspicion to and what happens then.
- Payment instructions by email get processed without a callback when the sender looks familiar.
Why this happens
Security training is frequently designed as compliance: once a year, the same for everyone, with generic content. It creates an awareness that fades within two weeks and conveys a picture of attacks that bears little resemblance to reality. At the same time, a culture in which a mistake counts as misconduct prevents exactly the behaviour that matters in an emergency: immediate reporting. In a successful attack, time is the decisive factor.
How we go about it
- Show real patterns. We work with examples that fit your company: forged invoices from your actual suppliers, requests in the name of your management, calls from supposed providers. Those examples stick, generic warnings do not.
- Train short and often. We use short units several times a year rather than one long annual session, supplemented by targeted content for particularly exposed areas such as finance, purchasing, sales and HR.
- Build a reporting culture. We set up a simple reporting route, ensure the reporting person gets feedback and make clear that reporting after a click is expressly wanted. Managers have to model that.
- Measure the effect and adjust. We measure how many reports arrive and how quickly, and use test campaigns with a sense of proportion. The aim is a rising reporting rate, not a falling click rate at any cost.
What you gain
- Suspicious cases reported within minutes rather than not at all.
- Staff who recognise the patterns actually in use.
- Evidence of completed training for audits and customers.
From our projects
The most important metric is not how many people click a test message but how many report it and how fast. A company where ten percent click and half of them report within minutes is in better shape than one with a low click rate and not a single report. We therefore set up the reporting route first and train afterwards. The second recurring finding: test campaigns without prior announcement of the procedure damage trust. We agree them in advance with management and, where one exists, with the works council, and evaluate them exclusively in anonymised form.
Good to know
For companies within the scope of the German BSI Act, training is part of the duties, and members of management have to attend training themselves in order to be able to assess risks. Independently of that, since 2 February 2025 Article 4 of the AI Act requires that staff using AI systems have a sufficient level of AI literacy. Both requirements can be combined into one training concept. Where test campaigns are evaluated in a personally identifiable way, data protection and codetermination have to be observed, which is why anonymised evaluation should be the rule.
Häufige Fragen
How often should we train?
A short unit per quarter has proven itself, supplemented by ad hoc notices when a new wave of attacks appears. A single long session per year satisfies documentation duties but changes behaviour hardly at all. For new staff a unit belongs in the onboarding, within the first few days.
What do we do when someone has fallen for a phishing email?
Have it reported immediately, lock the account or reset the password, end affected sessions, check devices and document it. What matters is how the person is treated: anyone who answers a report with consequences will not receive a report next time. The mistake is the click, the damage comes from the time until the response.
Let us talk about Training and awareness
In a thirty minute first call we work out where your biggest lever sits and whether we are the right people for it.
Further reading
Back to the field Security and Resilience